Skip to main content
AORBIT is designed against the control frameworks that govern Saudi and regional financial institutions:
  • SAMA Cyber Security Framework (CSF) — in-tenant deployment, audit integrity, and access-control design mapped control-by-control.
  • NCA Essential Cybersecurity Controls (ECC) — covered as part of the sovereign deployment profile.
  • PDPL — data-residency by architecture: personal data never leaves your perimeter because inference and state run inside it.
  • PCI DSS — scope statement for the Payments stream on national rails (mada · SADAD · Sarie).
  • SOC 2 / ISO 27001 — certification roadmap available on request.
The control-by-control mapping workbooks (Control ID → requirement → AORBIT capability → evidence) are working compliance documents, maintained per release and shared with customer risk and compliance teams during evaluation.